Improper File Control in Google App Engine Python SDK by Google
CVE-2011-4211

Currently unrated

Key Information:

Vendor

Google

Vendor
CVE Published:
30 October 2011

What is CVE-2011-4211?

A vulnerability exists in the FakeFile implementation of the Google App Engine Python SDK prior to version 1.5.4, which fails to properly restrict file opening. This lapse allows local users to circumvent access controls, potentially enabling the creation of arbitrary files through manipulated parameters. This incident poses significant risks by compromising file integrity and system security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.